CVE-2022-36803: High severity atlassian jira align vulnerability
Published Oct 14, 2022
·Updated
The MasterUserEdit API in Atlassian Jira Align Server before version 10.109.2 allows An authenticated attacker with the People role permission to use the MasterUserEdit API to modify any users role to Super Admin. This vulnerability was reported by Jacob Shafer from Bishop Fox.
Affected Software
1 affected component
Atlassian Jira Align<10.109.2
Event History
Oct 14, 2022
CVE Published
via MITRE·03:45 AM
Data Sourced
via MITRE·03:45 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-36803.
2
What is the severity of CVE-2022-36803?
The severity of CVE-2022-36803 is high with a severity value of 8.8.
3
What is affected by CVE-2022-36803?
Atlassian Jira Align Server before version 10.109.2 is affected by CVE-2022-36803.
4
How does CVE-2022-36803 work?
An authenticated attacker with the People role permission can use the MasterUserEdit API to modify any user's role to Super Admin.
5
Is there a fix for CVE-2022-36803?
Yes, updating Atlassian Jira Align Server to version 10.109.2 or later will fix CVE-2022-36803.